CVE-2025-31727
CVE-2025-31727
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Productos afectados
Jenkins Project · Jenkins AsakusaSatellite Plugin¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →